LOWVulnerability
CVE-2026-86194
Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymous visitors to execute form actions defined on login-restricted or unpublished pages. Attackers can POST to any public page with a restricted form's name to trigger save, upload, email, or call actions without authentication.
Properties
- cve_id
- CVE-2026-86194
- signal_observed_at
- 2026-09-18T21:50:21+00:00
- published_at
- 2026-09-05T13:18:14.727
- last_modified
- 2026-09-18T18:17:18.397
Related Entities (2)
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]Missing Authorization
Explore deeper with Ninja Signal's threat intelligence graph